|
71
|
8.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remo…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9330
|
2026-06-5 01:52 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
5.5 |
MEDIUM
Local
|
pypa
|
pip
|
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed out…
New
|
CWE-22
Path Traversal
|
CVE-2026-8643
|
2026-06-5 01:52 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
6.8 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticate…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45810
|
2026-06-5 01:51 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
7.1 |
HIGH
Network
|
nextcloud
|
tables
|
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the …
New
|
CWE-89
SQL Injection
|
CVE-2026-45722
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
5.9 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful …
New
|
CWE-287
Improper Authentication
|
CVE-2026-45691
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
5.9 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed atta…
New
|
CWE-287
Improper Authentication
|
CVE-2026-45690
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
8.2 |
HIGH
Network
|
nextcloud
|
tables
|
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker wi…
New
|
CWE-89
SQL Injection
|
CVE-2026-45545
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
4.3 |
MEDIUM
Network
|
nextcloud
|
tables
|
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. Th…
New
|
CWE-1230
Exposure of Sensitive Information Through Metadata
|
CVE-2026-45544
|
2026-06-5 01:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
5.3 |
MEDIUM
Network
|
nextcloud
|
forms
|
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the af…
New
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2026-45543
|
2026-06-5 01:43 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characte…
New
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-5078
|
2026-06-5 01:40 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|